ID

VAR-202405-0861


CVE

CVE-2024-26993


TITLE

Linux  of  Linux Kernel  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2024-015454

DESCRIPTION

In the Linux kernel, the following vulnerability has been resolved: fs: sysfs: Fix reference leak in sysfs_break_active_protection() The sysfs_break_active_protection() routine has an obvious reference leak in its error path. If the call to kernfs_find_and_get() fails then kn will be NULL, so the companion sysfs_unbreak_active_protection() routine won't get called (and would only cause an access violation by trying to dereference kn->parent if it was called). As a result, the reference to kobj acquired at the start of the function will never be released. Fix the leak by adding an explicit kobject_put() call when kn is NULL. Linux of Linux Kernel Exists in unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state. The RUGGEDCOM RST2428P is a Layer 2 Ethernet switch based on the SINEC operating system with up to 28 non-blocking interfaces. SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLCs) or human-machine interfaces (HMIs). Multiple vulnerabilities in third-party components of Siemens' SINEC OS could allow attackers to gain control of the server. The following advisory data is extracted from: https://access.redhat.com/security/data/csaf/v2/advisories/2024/rhsa-2024_7003.json Red Hat officially shut down their mailing list notifications October 10, 2023. Due to this, Packet Storm has recreated the below data as a reference point to raise awareness. It must be noted that due to an inability to easily track revision updates without crawling Red Hat's archive, these advisories are single notifications and we strongly suggest that you visit the Red Hat provided links to ensure you have the latest information available if the subject matter listed pertains to your environment. - Packet Storm Staff ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security update Advisory ID: RHSA-2024:7003-03 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2024:7003 Issue date: 2024-09-24 Revision: 03 CVE Names: CVE-2024-26993 ==================================================================== Summary: An update for kernel-rt is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description: The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: TIPC message reassembly use-after-free remote code execution vulnerability (CVE-2024-36886) * kernel: fs: sysfs: Fix reference leak in sysfs_break_active_protection() (CVE-2024-26993) * kernel: wifi: mac80211: Avoid address calculations via out of bounds array indexing (CVE-2024-41071) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution: https://access.redhat.com/articles/11258 CVEs: CVE-2024-26993 References: https://access.redhat.com/security/updates/classification/#important https://bugzilla.redhat.com/show_bug.cgi?id=2277238 https://bugzilla.redhat.com/show_bug.cgi?id=2278314 https://bugzilla.redhat.com/show_bug.cgi?id=2300448

Trust: 2.25

sources: NVD: CVE-2024-26993 // JVNDB: JVNDB-2024-015454 // CNVD: CNVD-2025-19346 // PACKETSTORM: 181781

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-19346

AFFECTED PRODUCTS

vendor:linuxmodel:kernelscope:eqversion:6.9

Trust: 1.8

vendor:linuxmodel:kernelscope:ltversion:4.15

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:6.2

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:5.16

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.18.6

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:4.5

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.14.68

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.9.125

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:5.15.157

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.4.154

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:3.19

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:3.18.121

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:4.19

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:6.6.29

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:6.1.88

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:3.16.62

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:6.8.8

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:4.19

Trust: 1.0

vendor:linuxmodel:kernelscope:gteversion:6.7

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:4.10

Trust: 1.0

vendor:linuxmodel:kernelscope:ltversion:3.17

Trust: 1.0

vendor:linuxmodel:kernelscope:eqversion:6.2 that's all 6.6.29

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:4.18.6 that's all 4.19

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:3.18.121 that's all 3.19

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:4.19 that's all 5.15.157

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:4.9.125 that's all 4.10

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:4.14.68 that's all 4.15

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:4.4.154 that's all 4.5

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:6.7 that's all 6.8.8

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:3.16.62 that's all 3.17

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion:5.16 that's all 6.1.88

Trust: 0.8

vendor:linuxmodel:kernelscope:eqversion: -

Trust: 0.8

vendor:siemensmodel:ruggedcom rst2428pscope:ltversion:v3.1

Trust: 0.6

vendor:siemensmodel:scalance xc-300/xr-300/xc-400/xr-500wg/xr-500 familyscope:ltversion:v3.1

Trust: 0.6

vendor:siemensmodel:scalance xcm-/xrm-/xch-/xrh-300 familyscope:ltversion:v3.1

Trust: 0.6

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-015454 // NVD: CVE-2024-26993

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2024-26993
value: MEDIUM

Trust: 1.0

NVD: CVE-2024-26993
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2025-19346
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-19346
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2024-26993
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2024-26993
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-015454 // NVD: CVE-2024-26993

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:others (CWE-Other) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-015454 // NVD: CVE-2024-26993

TYPE

code execution

Trust: 0.1

sources: PACKETSTORM: 181781

PATCH

title:Linux Kernel Archivesurl:https://git.kernel.org/stable/c/43f00210cb257bcb0387e8caeb4b46375d67f30c

Trust: 0.8

title:Patch for Multiple vulnerabilities in Siemens SINEC OS third-party componentsurl:https://www.cnvd.org.cn/patchInfo/show/723071

Trust: 0.6

sources: CNVD: CNVD-2025-19346 // JVNDB: JVNDB-2024-015454

EXTERNAL IDS

db:NVDid:CVE-2024-26993

Trust: 2.7

db:SIEMENSid:SSA-613116

Trust: 1.6

db:SIEMENSid:SSA-265688

Trust: 1.0

db:JVNDBid:JVNDB-2024-015454

Trust: 0.8

db:CNVDid:CNVD-2025-19346

Trust: 0.6

db:PACKETSTORMid:181781

Trust: 0.1

sources: CNVD: CNVD-2025-19346 // PACKETSTORM: 181781 // JVNDB: JVNDB-2024-015454 // NVD: CVE-2024-26993

REFERENCES

url:https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html

Trust: 1.8

url:https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html

Trust: 1.8

url:https://cert-portal.siemens.com/productcert/html/ssa-613116.html

Trust: 1.6

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/damsozxjepuoxw33wzywcvay7z5s7ooy/

Trust: 1.0

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/gcbzzec7l7ktwwas2nljk6so3izil4ww/

Trust: 1.0

url:https://git.kernel.org/stable/c/5d43e072285e81b0b63cee7189b3357c7768a43b

Trust: 1.0

url:https://git.kernel.org/stable/c/ac107356aabc362aaeb77463e814fc067a5d3957

Trust: 1.0

url:https://git.kernel.org/stable/c/a4c99b57d43bab45225ba92d574a8683f9edc8e4

Trust: 1.0

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4ez6pjw7voz224td7n4jznu6kv32zj53/

Trust: 1.0

url:https://cert-portal.siemens.com/productcert/html/ssa-265688.html

Trust: 1.0

url:https://git.kernel.org/stable/c/43f00210cb257bcb0387e8caeb4b46375d67f30c

Trust: 1.0

url:https://git.kernel.org/stable/c/84bd4c2ae9c3d0a7d3a5c032ea7efff17af17e17

Trust: 1.0

url:https://git.kernel.org/stable/c/f28bba37fe244889b81bb5c508d3f6e5c6e342c5

Trust: 1.0

url:https://git.kernel.org/stable/c/a90bca2228c0646fc29a72689d308e5fe03e6d78

Trust: 1.0

url:https://git.kernel.org/stable/c/57baab0f376bec8f54b0fe6beb8f77a57c228063

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-26993

Trust: 0.9

url:https://access.redhat.com/errata/rhsa-2024:7003

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=2300448

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=2278314

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.1

url:https://access.redhat.com/articles/11258

Trust: 0.1

url:https://access.redhat.com/security/data/csaf/v2/advisories/2024/rhsa-2024_7003.json

Trust: 0.1

url:https://bugzilla.redhat.com/show_bug.cgi?id=2277238

Trust: 0.1

sources: CNVD: CNVD-2025-19346 // PACKETSTORM: 181781 // JVNDB: JVNDB-2024-015454 // NVD: CVE-2024-26993

CREDITS

Red Hat

Trust: 0.1

sources: PACKETSTORM: 181781

SOURCES

db:CNVDid:CNVD-2025-19346
db:PACKETSTORMid:181781
db:JVNDBid:JVNDB-2024-015454
db:NVDid:CVE-2024-26993

LAST UPDATE DATE

2026-06-19T20:58:08.677000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-19346date:2025-08-22T00:00:00
db:JVNDBid:JVNDB-2024-015454date:2024-12-24T06:43:00
db:NVDid:CVE-2024-26993date:2026-05-12T12:16:29.237

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-19346date:2025-08-12T00:00:00
db:PACKETSTORMid:181781date:2024-09-24T14:00:45
db:JVNDBid:JVNDB-2024-015454date:2024-12-24T00:00:00
db:NVDid:CVE-2024-26993date:2024-05-01T06:15:17.110